Palo Alto Networks Cloud Security Professional Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 196 questions. Use the simulator for timed and flashcard mode. Or, view 337 more questions in the alternate version PCCSE 337 Questions.

Try Simulator

Cloud-Security-Professional Sample Questions

  1. Question 1

    Q1

    A financial institution is using Cortex Cloud's DSPM capabilities to classify data across their multi-cloud environment. A security analyst discovers that several newly provisioned AWS S3 buckets containing financial projections are not being scanned or classified. All existing buckets are scanned correctly. What is the most likely reason for this failure?

    Show answer & explanation

    Correct answer: C

    Cortex Cloud often relies on specific configurations for resource discovery, especially in large environments. A common practice is to configure the cloud account onboarding to only discover and scan resources that have a specific tag. This prevents accidental scanning of non-production or irrelevant assets. If new buckets are created without this tag, the DSPM scanner will ignore them, which is the most probable cause given that existing buckets are scanned correctly.

  2. Question 2

    Q2

    A DevOps team is managing a large-scale Kubernetes environment. A recent KSPM scan from Cortex Cloud flagged numerous workloads for violating the CIS Kubernetes Benchmark regarding immutable file systems. Which of the following configurations in a Kubernetes pod security context would proactively enforce this best practice?

    Show answer & explanation

    Correct answer: C

    The readOnlyRootFilesystem: true setting in a pod's security context directly enforces an immutable file system at the container level. This prevents any process, even one running as root inside the container, from writing to the root filesystem. This is a critical security control that aligns with the CIS Benchmark for Kubernetes and mitigates many runtime threats by preventing attackers from modifying binaries or configuration files.

  3. Question 3

    Q3

    A security architect is designing a runtime protection strategy for a serverless application composed of AWS Lambda functions. The primary concern is detecting and blocking malicious activity, such as command injection, within the function's execution environment. Which Cortex Cloud Defender type is specifically designed for this purpose?

    Show answer & explanation

    Correct answer: D

    The Cortex Cloud Serverless Defender is specifically engineered to protect serverless functions like AWS Lambda. It is deployed as a Lambda layer, which allows it to be attached to the function without modifying the core application code. This layer instruments the runtime environment to monitor for and block malicious activities, enforce security policies, and provide visibility into vulnerabilities within the function's dependencies.

  4. Question 4

    Q4

    During a CI/CD pipeline run for a containerized application, the Cortex Cloud SCA scan fails the build. The scan report indicates a critical vulnerability (CVE-2024-XXXX) in an open-source library, log-utils.js, which is a transitive dependency of a directly imported package. What is the most effective and immediate action a developer can take to remediate this issue and allow the pipeline to proceed securely?

    Show answer & explanation

    Correct answer: B

    The most secure and proper way to fix a vulnerability in a transitive dependency is to update the direct dependency that pulls it in. Modern package managers will resolve the dependency tree and pull a patched, non-vulnerable version of the transitive dependency if one is available in the updated direct package. This addresses the root cause rather than simply suppressing an alert, ensuring the code is actually secure.

  5. Question 5

    Q5Multiple answers

    A SOC analyst receives a high-severity alert from Cortex CDR indicating suspicious lateral movement between two EC2 instances. The alert provides the source and destination IP addresses, the protocol used (SSH), and a MITRE ATT&CK mapping to T1021.004 (Remote Services: SSH). To effectively investigate and contain this threat, which TWO actions should the analyst perform first using the CDR module? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

  6. Question 6

    Q6

    True or False: The primary function of AI Security Posture Management (AI-SPM) in Cortex Cloud is to use AI to detect misconfigurations in standard cloud resources like storage buckets and virtual machines.

    Show answer & explanation

    Correct answer: B

    This statement is false. Using AI to detect misconfigurations in standard cloud resources is a function of advanced CSPM. The primary function of AI-SPM is to secure the AI models and pipelines themselves, protecting against risks like model theft, data poisoning, and insecure configurations of AI/ML services (e.g., Azure Machine Learning, Amazon SageMaker).

  7. Question 7

    Q7

    Case Study:

    A rapidly growing e-commerce company, ShopFast, has deployed its entire infrastructure on Google Cloud Platform (GCP). Their environment consists of a Kubernetes cluster (GKE) for microservices, Cloud SQL for databases, and Cloud Storage for static assets. The CISO is concerned about the company's identity and access management posture after a security audit revealed numerous service accounts with overly permissive, project-level roles like 'Editor'. The goal is to enforce the principle of least privilege without disrupting critical application functions.

    The security team uses Cortex Cloud for posture management. They need to identify all service accounts that have permissions they have never used and automatically generate recommendations for tightened IAM policies. The team must then be able to review these recommendations and apply them in a safe, controlled manner.

    Which Cortex Cloud capability is specifically designed to address this requirement?

    Show answer & explanation

    Correct answer: C

    The scenario described is the core use case for Cloud Infrastructure Entitlement Management (CIEM), which is a key part of the Identity Security module. CIEM analyzes actual usage data (e.g., from GCP audit logs) to determine which permissions granted to an identity (like a service account) are excessive because they have never been used. It then automatically generates right-sized, least-privilege IAM policies that can be reviewed and applied, directly addressing the CISO's requirements.

  8. Question 8

    Q8

    A security engineer is configuring a WAAS policy in Cortex Cloud to protect a web application from OWASP Top 10 threats. The application uses a custom HTTP header, X-Transaction-ID, to track user sessions. A recent penetration test showed that this header is vulnerable to SQL injection. How should the engineer configure the WAAS policy to specifically mitigate this vulnerability without affecting other headers?

    Show answer & explanation

    Correct answer: B

    While default protections are good, a targeted vulnerability in a custom header requires a specific rule. The most precise and effective method is to create a custom WAAS rule that singles out the X-Transaction-ID header and applies SQL injection pattern matching only to its value. This ensures the vulnerability is mitigated without the performance overhead or potential for false positives that might come from inspecting every header with the same level of scrutiny.

  9. Question 9

    Q9

    A cloud administrator is tasked with deploying Cortex Host Defenders to a fleet of 500 virtual machines running in Azure. The goal is to automate the deployment process fully, ensuring that any new VM added to a specific resource group is automatically protected. Which deployment method should be used?

    Show answer & explanation

    Correct answer: B

    Azure VM Extensions are the native and most effective way to automate the deployment and lifecycle management of software on Azure VMs. Cortex Cloud provides a specific VM Extension for the Host Defender. This method allows the administrator to define the deployment declaratively (e.g., in an ARM template or via Azure Policy) and ensures that the agent is automatically installed on both existing and future VMs within the targeted scope, fulfilling the automation requirement.

  10. Question 10

    Q10

    A security team is using Cortex Cloud's IaC scanning to secure its Terraform code before deployment. The scanner flags a resource for having a hardcoded password. Which Terraform feature should the team use to manage this secret securely and resolve the IaC scan finding?

    resource "aws_db_instance" "default" {
    allocated_storage = 10
    engine = "mysql"
    engine_version = "5.7"
    instance_class = "db.t3.micro"
    name = "mydb"
    username = "foo"
    password = "____" # IaC Scanner flags this line
    parameter_group_name = "default.mysql5.7"
    skip_final_snapshot = true
    }
    
    Show answer & explanation

    Correct answer: C

    The best practice for managing secrets in Terraform is to never hardcode them. Instead, you should use a Terraform data source to dynamically fetch the secret from a secure, external secrets management system (e.g., AWS Secrets Manager, Azure Key Vault, HashiCorp Vault) at runtime. This approach prevents the secret from being stored in source control, resolves the IaC scanner finding, and aligns with security best practices.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the Cloud-Security-Professional sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 533 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon